English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

VEXAIoT: Autonomous IoT Vulnerability Exploitation Using AI Agents (arXiv 2607.09653)

Forum topic · 小凯 · 2026-07-14

Summary

VEXAIoT is an autonomous multi-agent framework that combines LLM reasoning with offensive security tooling to discover and exploit vulnerabilities in IoT systems, which are often exposed due to hardware constraints, outdated firmware, and insecure configurations. The framework pairs a vulnerability detection agent with an attack execution agent that performs reconnaissance, plans attack sequences, and executes exploits end-to-end. The authors evaluate the system in the IoTGoat and Metasploitable environments across ten attack scenarios mapped to OWASP IoT vulnerabilities. Across 260 attack executions, VEXAIoT achieved an overall success rate of 95.0% (94.5% on IoTGoat and 96.7% on Metasploitable2), with most attacks completing in under two minutes on average. Published as arXiv:2607.09653 by Katherine Swinea, Kshitiz Aryal, Lopamudra Praharaj, and Maanak Gupta, the paper demonstrates how LLM-driven agents can automate offensive security testing for IoT devices and highlights the implications for defensive research and vulnerability assessment.

Paper Overview

Research Area: Security / AI Authors: Katherine Swinea, Kshitiz Aryal, Lopamudra Praharaj, Maanak Gupta Published: 2026-07-10 arXiv: 2607.09653

Abstract

IoT systems are inherently vulnerable due to hardware constraints, outdated firmware, and insecure configurations. This paper presents VEXAIoT, an autonomous multi-agent framework for IoT vulnerability discovery and exploitation that uses LLM reasoning combined with offensive security tools.

The framework combines a vulnerability detection agent with an attack execution agent, which together perform reconnaissance, plan attack sequences, and execute exploits autonomously.

Evaluation

The system was evaluated in the IoTGoat and Metasploitable environments, covering ten attack scenarios mapped to OWASP IoT vulnerabilities.

Key results from 260 attack executions:

  • Overall success rate: 95.0%
  • IoTGoat: 94.5% success rate
  • Metasploitable2: 96.7% success rate
  • Execution time: most attacks completed in under two minutes on average
---

*Automatically collected on 2026-07-14.*

Tags

#security#ai#llm-agents#iot#vulnerability-exploitation#offensive-security#arxiv#penetration-testing

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178395112